Google AI: 100+ Critical Software Flaws Found in 2 Days
Summary
Google's AI security agents found over 100 critical software vulnerabilities in just two days. This was during a live investigation into stolen corporate repositories. The tool, called the Agentic Vulnerability Discovery Harness or AVDH, has been used internally by Mandiant for ten months. It has scanned millions of lines of code and generated tens of thousands of findings. Researchers state it uncovered dozens of assignable flaws in widely used web extensions and open-source projects. This led to 12 assigned CVEs, with more currently in active disclosure. The AVDH works through a sequence of specialized AI agents. These agents handle tasks like threat modeling, finding entry points for user input, and enriching context. Other agents generate hypotheses for security problems such as access-control issues or dangerous data flows. Finally, validation agents weigh in on each hypothesis, and a synthesis agent sorts the findings. Every confirmed finding is then reviewed by a person. Mandiant consultants reproduce the exploit and run proof-of-concept code to verify the flaw. This human validation helps reduce false alarms, which are common with automated code scanners. The bottom line is that AI is proving to be a powerful new tool in the ongoing fight to secure software from vulnerabilities.
This is an AI-generated audio summary. Always check the original source for complete reporting.